CVE-2022-36062

Grafana folders admin only permission privilege escalation

Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.


We have discovered 106 live websites that are affected by CVE-2022-36062.

Run a Free Instant Scan




Affected Software

Product  Grafana
Category Analytics
Vulnerable Domains106 live websites (13% of Grafana install base)
Vulnerable Versions
  • from 0 through 8.5.13
  • from 9 through 9.0.9
  • from 9.1 through 9.1.6
Vulnerable Versions Count23 versions ( 26% of all versions)


Common Weakness Enumeration

CWE-281 Improper Preservation of Permissions



Details

  • Published - Sep 22, 2022
  • Updated - Apr 23, 2025

Website Distribution by Country

Number of websites using CVE-2022-36062
United States36 websites



Germany25 websites
France7 websites
Russia6 websites
Netherlands4 websites
Australia2 websites
Switzerland2 websites
Italy2 websites
Poland2 websites

Website Distribution by TLD

Number of websites using CVE-2022-36062
.com20 websites
.org15 websites
.de10 websites
.eu7 websites
.ru6 websites
.ch4 websites
.net3 websites
.pl2 websites
.it2 websites
.info2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-36062

Top websites that are affected by CVE-2022-36062. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
****.********.org United States*,***,***
*******.*******.edu United States*,***,***
********************.com United States*,***,***
*****.com United States*,***,***
*****.********.org Germany*,***,***
***.******.org Italy*,***,***
*******.*********.audio Germany**,***,***
*********.*******.eu United States**,***,***
********.fr France**,***,***
See full domain list

FAQ

CVE-2022-36062 is Improper Preservation of Permissions in Grafana
A total of 106 websites have been identified as vulnerable to CVE-2022-36062, based on global website indexing conducted by WebTechSurvey.
The Grafana is affected by the CVE-2022-36062 vulnerability.
Grafana versions up to 9.1.6 are vulnerable to CVE-2022-36062.
CVE-2022-36062 is resolved in version 9.1.6 of Grafana.